Path to this page:
Subject: CVS commit: pkgsrc/www
From: Nia Alarie
Date: 2023-08-08 17:46:58
Message id: 20230808154658.4D859FBDB@cvs.NetBSD.org
Log Message:
firefox102: Update to 102.14.0
Security Vulnerabilities fixed in Firefox ESR 102.14
#CVE-2023-4045: Offscreen Canvas could have bypassed cross-origin
restrictions
#CVE-2023-4046: Incorrect value used during WASM compilation
#CVE-2023-4047: Potential permissions request bypass via clickjacking
#CVE-2023-4048: Crash in DOMParser due to out-of-memory conditions
#CVE-2023-4049: Fix potential race conditions when releasing platform
objects
#CVE-2023-4050: Stack buffer overflow in StorageManager
#CVE-2023-4054: Lack of warning when opening appref-ms files
#CVE-2023-4055: Cookie jar overflow caused unexpected cookie jar state
#CVE-2023-4056: Memory safety bugs fixed in Firefox 116, Firefox ESR 115.1,
Firefox ESR 102.14, Thunderbird 115.1, and Thunderbird 102.14
Files: